SB2018020806 - Denial of service in Cisco Virtualized Packet Core
Published: February 8, 2018
Security Bulletin ID
SB2018020806
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Denial of service (CVE-ID: CVE-2018-0117)
The vulnerability allows a remote attacker to cause DoS condition on the target system.The weakness in the ingress packet processing functionality of the Cisco Virtualized Packet Core-Distributed Instance (VPC-DI) Software due to improper handling of user-supplied input. A remote attacker can send malicious traffic to the internal distributed instance (DI) network address, trigger an unhandled error condition, cause the CF instances and the entire VPC to reload, resulting in the disconnection of all subscribers and denial of service.
Remediation
Install update from vendor's website.